rubygems/rubygems.org
49.0
Weak · 19 September 2026
25.3k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is the RubyGems.org application, a platform for hosting and distributing Ruby software packages. It provides core functionality for users to manage gem versions, handle ownership and organizational structures, and interact with a comprehensive REST API for programmatic access. The system also features a secure, GitHub-authenticated admin dashboard for monitoring metrics, auditing changes, and performing maintenance tasks on the gem ecosystem.
How it got here
2009–2014 — Platform modernization and security hardening
45 changes.
This period focused on a comprehensive modernization of the RubyGems.org platform, upgrading the core stack to Rails 8.1 and Ruby 3.4 while implementing a new Docker-based development environment. Significant effort was dedicated to security hardening through the introduction of API key management, OIDC integration, HIBP password checks, and Sigstore attestation support. The work also encompassed a complete UI redesign with Tailwind CSS, a migration to Playwright for testing, and the restructuring of the API and background job infrastructure.
2015–2023 — OIDC integration and admin overhaul
85 changes.
This period focused on implementing OpenID Connect support for trusted publishers and API key roles, alongside a comprehensive redesign of the admin dashboard using Avo and GitHub OAuth. The work also included migrating the view layer to Phlex, standardizing styling with Tailwind CSS, and significantly expanding test coverage across API, model, and administrative features.
2024–2026 — Organizations and security infrastructure
43 changes.
This period focused on introducing multi-tenant organization management, including onboarding flows, membership controls, and gem transfer workflows. It also established a robust security foundation through structured event logging, RSTUF artifact integration, and comprehensive API authorization policies. The frontend was modernized by migrating to vanilla JavaScript and Stimulus, while the admin panel was upgraded to Avo 3.
Features
Add Rails 4-style binstubs and development tooling scripts
The bin directory now includes standard Rails binstubs (rails, rake, bundle) alongside new scripts for development and testing: bin/ci for local continuous integration, bin/dev for running the Rails server, bin/herb for HTML parsing, bin/importmap for asset management, bin/playwright and bin/prettier for system testing and JavaScript linting, bin/brakeman and bin/rubocop for security and code quality checks, and bin/setup/bin/update for environment provisioning and database migrations.
bin · high confidence
Add WebAuthn credential management UI
Users can now register and manage WebAuthn security devices directly from the profile view. The new interface includes a form to add a new device with a nickname and a list view to display existing credentials, each with a delete button that prompts for confirmation before removal.
_app/views/webauthn\credentials · high confidence
Add internal ping and revision endpoints
The application now exposes two new internal API endpoints for health monitoring and version tracking. The /ping endpoint returns a simple "PONG" response to verify service availability, while the /revision endpoint returns the current application version string via AppRevision.version, allowing operators to confirm which code version is currently deployed.
app/controllers/internal · high confidence
Add organization invitation email templates
Added HTML and text email templates for the organization invitation flow, allowing users to receive notifications when invited to join an organization. The HTML template includes a styled 'ACCEPT INVITATION' button, while the text template provides a plain-text version with the acceptance URL.
_app/views/organization\mailer · high confidence
Admin audit trail now shows detailed field-level diffs
Administrators can now view a structured, field-by-field comparison of record changes within the Avo admin interface. This new \AuditedChangesRecordDiff::ShowComponent\ renders a visual diff that highlights added, modified, and removed fields using distinct color coding (green for new, orange for changed, red for old), allowing admins to quickly understand exactly what data was altered in an audit entry.
_app/components/avo/audited\_changes\_record\diff · high confidence
Admin dashboard now displays a personalized welcome card
The admin dashboard now includes a new welcome card component that displays a message identifying the currently logged-in administrator. This card provides a direct link to the admin user's profile page, allowing for quick navigation to account details upon logging into the Avo admin interface.
app/views/avo/cards · high confidence
Custom Avo field implementations for arrays, nested records, and JSON viewing
The admin interface now includes several new custom Avo field types to improve data handling and display. The ArrayOfField and NestedField allow for the editing and display of complex, nested data structures within resources. A new JsonViewerField provides a formatted, syntax-highlighted view for JSON content. Additionally, the GlobalIdField and SelectRecordField offer specialized handling for GlobalID references and record selection, while the EventAdditionalField dynamically renders event-specific attributes based on their type.
app/avo/fields · high confidence
Expanded admin dashboard resource coverage
The admin dashboard now includes dedicated resource controllers for a broader set of data models, enabling administrators to view and manage additional entities directly. New controllers have been added for GitHub users, API keys and their scopes, attestations, audit logs, blocked email domains, deletions, dependencies, email allowlists, event associations, gem downloads, gem name reservations, gem typo exceptions, GeoIP info, IP addresses, link verifications, link sets, log tickets, maintenance task runs, memberships, OIDC providers and roles, pending trusted publishers, organization invites and onboarding, organizations, ownerships, RubyGems, SendGrid events, subscriptions, users, versions, webhooks, and WebAuthn credentials. This expands the administrative interface's visibility into system state and operational records.
app/controllers/avo · high confidence
Initial RSTUF API client implementation
Added a new RSTUF API client (\lib/rstuf/client.rb\) that enables interaction with the RSTUF service. This client provides methods to post and delete artifacts, as well as check the state of tasks, using Faraday for HTTP communication and JSON serialization. It includes error handling for API failures and logging capabilities.
lib/rstuf · high confidence
Initial database schema and ownership model
The database is initialized with core tables for users, rubygems, versions, and dependencies, establishing the foundational data structure. A dedicated ownership model is introduced via the \ownerships\ table to manage gem permissions, replacing the previous single-owner design where \user\_id\ was stored directly on the \rubygems\ table. This change also includes the creation of supporting tables for linksets, subscriptions, web hooks, and delayed jobs, along with the initial indexing strategy to support query performance.
db/migrate · high confidence
Initial implementation of RSTUF artifact management jobs
Added a new set of background jobs (\Rstuf::AddJob\, \Rstuf::RemoveJob\, \Rstuf::CheckJob\) to handle uploading and deleting gem artifacts via the RSTUF service. \AddJob\ and \RemoveJob\ submit tasks to the RSTUF client and trigger a subsequent check, while \CheckJob\ monitors task status, supporting a new \PRE\_RUN\ state and implementing retry logic for transient states like \PENDING\ or \RUNNING\. The jobs are gated by \Rstuf.enabled?\ to ensure they only run when the feature is active.
app/jobs/rstuf · high confidence
Introduce OIDC-based trusted publisher and API key role models
This change adds the foundational data models for OIDC integration, enabling users to configure trusted publishers (currently GitHub Actions) and manage API key roles. The new \OIDC::Provider\ model stores OIDC provider configurations and JWKS, while \OIDC::ApiKeyRole\ links a user to a provider and defines permissions via \OIDC::ApiKeyPermissions\ (scopes and gem ownership). \OIDC::AccessPolicy\ allows fine-grained JWT validation using conditions like \string\_equals\ or \string\_matches\. \OIDC::IdToken\ records issued tokens, and \OIDC::PendingTrustedPublisher\ / \OIDC::RubygemTrustedPublisher\ handle the association of trusted publishers with specific gems, including validation for reserved names and availability.
app/models/oidc · high confidence
Introduce new model classes for API keys, attestations, and admin auditing
This change adds several new model classes to the application: \ApiKey\ (with polymorphic ownership, scopes, and MFA checks), \ApiKeyRubygemScope\ (linking API keys to specific gems), \Attestation\ (storing and validating Sigstore bundles), \Audit\ (tracking admin actions), \BlockedEmailDomain\ (managing email domain restrictions), \Admin::GitHubUser\ (storing admin GitHub users), \ApplicationModel\ (base for non-AR models), and \ApplicationRecord\ (base for AR models). These models support new features like API key management, gem attestation verification, admin auditing, and email domain blocking.
app/models · high confidence
Introduce organization management capabilities
This change introduces the backend controllers for the new Organizations feature, enabling users to create and manage organizational structures. Key capabilities include inviting and managing members (with support for resending invitations), reserving gem names, and viewing organization-owned gems. The implementation includes a base controller that enforces sign-in and MFA requirements, and specific controllers for handling membership invitations, member lists, gem name reservations, and onboarding completion.
app/controllers/organizations · high confidence
Introduce organization onboarding flow
Adds a new multi-step onboarding process for creating organizations, implemented via a dedicated controller namespace under app/controllers/organizations/onboarding. The flow guides users through setting the organization name and handle, selecting RubyGems to include, inviting team members (with the creator automatically assigned as owner), and confirming the setup. The controllers enforce authentication, MFA requirements, and feature flags, and use a shared layout and breadcrumbs for consistent navigation.
app/controllers/organizations/onboarding · high confidence
Introduce structured security and activity event logging
The application now records detailed, structured events for key user and system actions, including user account creation, login success, email changes, API key management, and RubyGem version pushes, yanks, and owner changes. This new event system captures contextual metadata such as IP address, geolocation, and parsed user-agent information (browser, OS, installer) to provide a comprehensive audit trail for security monitoring and administrative oversight.
app/models/events · high confidence
Introduces custom ActiveModel types for arrays, durations, GlobalIDs, and JSON
The application now includes four new custom type definitions in lib/types to handle specific data casting and serialization needs. The new Types::ArrayOf allows for generic array validation with member casting, while Types::Duration provides robust parsing and serialization of time intervals from strings, integers, or existing duration objects. Types::GlobalId simplifies the handling of GlobalID objects by automatically parsing string representations, and Types::JsonDeserializable ensures safe JSON serialization by normalizing nested structures to prevent unexpected output from Rails 8.1's JSON encoder.
lib/types · high confidence
New Admin GitHub User model for storing and validating admin accounts
A new \Admin::GitHubUser\ model has been added to persist GitHub user data for administrators. This model validates that admin users have the necessary OAuth tokens and info data, ensures they are members of the RubyGems organization, and provides methods to check team membership. It also sets up associations for auditing admin actions.
app/models/admin · high confidence
New Kubernetes deployment manifests for web, background jobs, and infrastructure
This change introduces a comprehensive set of Kubernetes configuration files for the application's deployment. The web service is now deployed as a Puma-based application with Datadog AppSec enabled, health probes, and resource limits. Background processing is handled by dedicated Good Job deployments for default, maintenance, and 'within 24 hours' queues, as well as a Shoryuken deployment for SQS-based tasks. Infrastructure includes a new Ingress resource using the networking.k8s.io/v1 API, an Nginx sidecar configuration for rate limiting and proxying, a CronJob for monthly version list updates, and a dedicated Pod for database migrations.
config/deploy · high confidence
New OIDC API endpoints for role assumption, trusted publishers, and token exchange
This change introduces a new set of API controllers under the OIDC namespace, enabling programmatic interaction with OpenID Connect features. The \ApiKeyRolesController\ allows users to list and assume OIDC API key roles, generating temporary API keys based on validated JWTs. The \TrustedPublisherController\ provides an endpoint to exchange OIDC tokens for RubyGems API keys, facilitating trusted publishing workflows. Additionally, the \RubygemTrustedPublishersController\ exposes CRUD operations for managing trusted publisher configurations on specific gems, while \ProvidersController\ and \IdTokensController\ provide read access to OIDC provider metadata and issued ID tokens respectively.
app/controllers/api/v1/oidc · high confidence
New OIDC API key roles and trusted publisher management interfaces
The application now provides dedicated controllers and views for managing OIDC (OpenID Connect) integration features. Users can create and manage API key roles with specific scopes and access policies via the new \OIDC::ApiKeyRolesController\. Additionally, new controllers handle the lifecycle of trusted publishers: \OIDC::PendingTrustedPublishersController\ allows users to create and manage pending publisher requests, while \OIDC::RubygemTrustedPublishersController\ enables gem maintainers to configure trusted publishers directly on their gem pages. Supporting controllers for OIDC providers (\OIDC::ProvidersController\) and ID tokens (\OIDC::IdTokensController\) are also introduced to allow users to view provider details and token history. These changes introduce stricter parameter validation using \params.expect\ and integrate session verification for security.
app/controllers/oidc · high confidence
New RubyGems transfer workflow for organizations
Users can now transfer ownership of RubyGems to an organization through a new multi-step onboarding flow. This change introduces a dedicated controller hierarchy (base, organizations, rubygems, users, confirmations, and transfers) that guides users through selecting a target organization, choosing which gems to transfer, assigning member roles, and confirming the action. The system supports bulk transfers in a single transaction and allows users to cancel pending or failed transfers.
app/controllers/rubygems · high confidence
New administrative rake tasks for data integrity, security, and maintenance
This change introduces a suite of new Rake tasks in lib/tasks to support various administrative and maintenance operations. Key additions include api\_keys:migrate to migrate legacy user API keys to the new ApiKey model, multifactor\_auth:migrate\_ui\_only to update user MFA levels, and audit\_attestation\_subject\_digest to verify attestation integrity against version SHA256 hashes. Data integrity is improved with tasks like compact\_index:correct\_info\_checksum, compact\_index:backfill\_yanked\_at, dependency:dangling\_rubygem\_id\_purge, and linkset:clean to fix checksums, backfill missing fields, and remove invalid URLs. Operational tasks include gemcutter:import:process for bulk gem imports, gemcutter:gem\_downloads:add\_rubygems\_record for download tracking, users:verify to block users with expired email domains, and memcached:flush for cache management. Developer tooling is also enhanced with format:ruby and format:js for code formatting, importmap:verify and importmap:pristine for JavaScript package management, and gen\_erd for generating entity-relationship diagrams.
lib/tasks · high confidence
New administrative scripts for user and gem management
A suite of new command-line scripts has been added to the \script/\ directory to streamline administrative tasks. These include \add\_owner\ to grant gem ownership, \block\_user\ to disable user accounts, \change\_email\ to update user email addresses, and \merge\_users\ to consolidate duplicate accounts. Security and maintenance capabilities are expanded with \disable\_mfa\ to reset two-factor authentication, \permadelete\ to permanently remove gems, \restore\_version\ to recover yanked gems, \reset\_api\_key\ to regenerate API keys, and \yank\_gem\ or \yank\_user\ to yank specific gems or all gems associated with a user. Additional utility scripts include \load-pg-dump\ for restoring database dumps, \release\_reserved\_namespace\ for freeing gem names, \update-rubygems\ for updating Ruby and RubyGems versions in the project configuration, \build\_docker.sh\ for building and testing Docker images, \dev\ for loading development secrets, and \s3\_utils.rb\ for S3 object management.
script · high confidence
New auditing capability for Avo resources
Added the \Auditable\ concern to Avo resources, enabling automatic tracking of database changes. This concern wraps create, update, and destroy actions in transactions, capturing before-and-after attribute states for all affected records and storing them in a new \Audit\ model. It also includes logic to normalize complex data structures for JSON serialization to ensure compatibility with Rails 8.1's JSON encoder.
app/avo/concerns · high confidence
New dedicated page for managing notification preferences
Users can now configure push and owner notification settings for their individual gems and organization memberships on a dedicated Notifiers page. The new interface allows users to toggle push notifications and owner notifications on or off for each gem they own and each organization they belong to, with recommended defaults indicated.
app/views/notifiers · high confidence
New email and scope boolean filters for admin dashboard
The admin dashboard now includes two new filter components: an Email filter that allows searching by email address using regular expressions, and a ScopeBoolean filter that enables filtering by multiple boolean scopes with default values. These additions enhance the admin interface's data filtering capabilities.
app/avo/filters · high confidence
New email notification for policy updates
Users will now receive an email announcement informing them that RubyGems.org is adopting new Terms of Service, Privacy Notice, Acceptable Use Policy, and Copyright Policy. The message details the review period concluding on June 4th and explains that a banner will appear on the site afterward prompting users to review and accept the new policies.
_app/views/policies\mailer · high confidence
New helper modules for API keys, OIDC, and ownership management
This change introduces a suite of new view helper modules to support recent feature additions in the application. The new \ApiKeysHelper\ provides logic for displaying API key scopes, including tooltips for soft-deleted gems, and manages the parameter processing for API key creation and updates. \OwnersHelper\ adds policy-based checks for adding, modifying, and removing gem owners, as well as displaying MFA and confirmation status. \OIDC::ApiKeyRolesHelper\ and \OIDC::ProvidersHelper\ are added to support the new OIDC integration for API keys. Additionally, \ApplicationHelper\ is updated with new methods for page titles, avatar rendering, and search fields, while \RubygemsHelper\ gains methods for subscription links, license display, and various sidebar links. Other new helpers include \AttestationsHelper\, \DurationHelper\, \DynamicErrorsHelper\, \IconHelper\, \ProseHelper\, \SearchesHelper\, \UsersHelper\, and \VersionsHelper\, each providing specific UI logic for their respective domains.
app/helpers · high confidence
New helper modules for compact index checksums and importmap verification
Added two new helper modules in lib/tasks/helpers: CompactIndexTasksHelper, which updates info checksums for gem versions (handling both indexed and yanked states), and ImportmapHelper, which provides a custom packager to verify and manage vendored JavaScript packages via jspm.io, including diff generation for verification failures.
lib/tasks/helpers · high confidence
New library modules for security, validation, and infrastructure
This change introduces a suite of new library components to enhance security, validation, and infrastructure management. Security is strengthened with \PasswordBreachChecker\ to validate passwords against the HIBP database, \GitHubSecretScanning\ for verifying secret scanning signatures, and \SearchQuerySanitizer\ to protect the search engine from DoS attacks by sanitizing user queries. Validation is improved with \GemValidator\ (including schema and package validation), \GemRequirementsValidator\, and \NameFormatValidator\ to enforce stricter gem metadata rules. Infrastructure and operational capabilities are added via \RubygemFs\ for S3/local storage abstraction, \Fastly\ for cache purging, \GemCachePurger\ for cache invalidation, \ElasticSearcher\ for search operations, and \Access\ for role-based permissions. Additional utilities include \AppRevision\ for version tracking, \CertificateChainSerializer\ for certificate handling, \ClearanceBackdoor\ for development login, \CompactIndex\ for vendored index logic, \ConfirmedUserGuard\ for email confirmation enforcement, \GemPackageEnumerator\ for efficient gem reading, \GitHubOAuthable\ for admin authentication, \JobTags\ for job tracking, \NestedValidator\ for complex validation, \Patterns\ for shared regex definitions, \RackAttackReset\ for rate-limit management, \RailsDevelopmentLogFormatter\ for logging, \Rstuf\ for feature toggling, \ShasumFormat\ for checksum handling, and \TraceTagger\ for Datadog integration.
lib · high confidence
New maintenance tasks for data integrity, security, and infrastructure
This update introduces a suite of new maintenance tasks to the application. For security and user management, it adds tasks to revoke cache-exposed API keys, notify affected users (including staggered notifications for inactive users), discard spam accounts, and yank/block users associated with specific API keys. For data integrity and backfilling, new tasks repair broken attestations, backfill gem platform information, populate spec SHA-256 checksums, link set links to version metadata, and backfill user WebAuthn IDs. Additionally, infrastructure tasks are added to verify gem contents in storage, upload info files to S3, and backfill compact index v2 information.
app/tasks · high confidence
New model concerns for MFA, search, and data integrity
This change introduces several new concerns in app/models/concerns. UserMultifactorMethods, UserTotpMethods, and UserWebauthnMethods consolidate and refactor multi-factor authentication logic, including TOTP and WebAuthn verification, MFA level management, and recovery code handling. RubygemSearchable integrates Searchkick for gem search, defining mappings and search data structures. CompactIndexVersions provides methods for generating compact index data. EmailDomainNormalization adds validation for email domains. PasswordResettable implements secure password reset token handling. AttestationBundleRepair adds logic to fix issues in Sigstore attestation bundles.
app/models/concerns · high confidence
New news page with tabbed navigation and pagination
A new view for the news section has been added, featuring a tabbed interface that allows users to toggle between 'All Gems' and 'Popular Gems'. The page displays a list of Ruby gems using a dedicated component and includes pagination controls to navigate through entries, with an info header indicating the current page range.
app/views/news · high confidence
New organization management interface with membership, gem, and reservation views
Users can now manage organizations through a dedicated set of views. The main dashboard lists all organizations the user belongs to and allows creating new ones. Inside an organization, users can view a history of gem activity, manage the list of gems owned by the organization, and view/edit member lists with invite capabilities. Additionally, organization owners can reserve gem names and edit organization settings like the display name.
app/views/organizations · high confidence
New owner notification and confirmation email templates
The owners mailer now uses new HTML and text email templates for notifying users when they are added to, removed from, or have their ownership role updated on a gem. These notifications include security guidance for unexpected changes and links to manage email preferences. Additionally, a new ownership confirmation flow has been introduced, requiring users to verify their ownership via a secure link with an expiration time.
_app/views/owners\mailer · high confidence
New password change and compromised password reset email templates
Users will now receive newly designed HTML and plain-text emails for password changes and compromised account notifications. The 'change password' email provides a direct link to reset the password, while the 'compromised password reset' email includes additional reassurance text and a link that specifies the reason for the reset, along with support contact information.
_app/views/password\mailer · high confidence
New v2 API endpoints for gem contents checksums and version details with Ruby ABI support
This change introduces two new controllers in the v2 API: \Api::V2::ContentsController\ and \Api::V2::VersionsController\. The contents controller exposes a new endpoint to retrieve content-addressable checksums (SHA256) for specific gem versions, supporting JSON, YAML, and plain text responses, while also validating that the requested version has associated checksums. The versions controller provides detailed payload information for a specific gem version, including platform and Ruby ABI variant resolution. Both endpoints now support filtering by \ruby\_abi\ (e.g., 3.2) alongside platform and version number, allowing users to target specific Ruby ABI variants when resolving and fetching version data. The implementation includes caching headers consistent with v1, strong parameter validation, and specific error handling for missing versions or unavailable content.
app/controllers/api/v2 · high confidence
Project initialization and development environment setup
This change establishes the foundational configuration for the RubyGems.org application, including a new Dockerfile for multi-stage builds, a docker-compose.yml for local services (PostgreSQL, Memcached, OpenSearch, Toxiproxy), and a .ruby-version file specifying Ruby 4.0.6. It introduces comprehensive linting and formatting rules via .rubocop.yml (targeting Ruby 4.0, using Prism parser) and .prettierignore, alongside a new .herb.yml for HTML validation. Documentation is updated with AGENTS.md for AI coding guidance, a new SECURITY.md, and a rewritten CONTRIBUTING.md detailing setup via Docker or DevContainers. The deployment tooling is updated to use Krane for Kubernetes, and the README is converted from Textile to Markdown.
(repo-wide) · high confidence
Publish RubyGems.org legal policy pages
The site now includes dedicated, viewable pages for its core legal policies: Terms of Service, Privacy Notice, Acceptable Use Policy, and Copyright Policy. These pages are rendered from Markdown files and linked from a new policies index, providing users with clear, accessible information on account security, data handling (including the use of ClickHouse for log analysis), content ownership, and enforcement procedures.
app/views/policies · high confidence
Staging deployment configuration and secrets initialization
The staging environment is now configured with a complete set of Kubernetes deployment manifests (web, jobs, shoryuken, maintenance, db-migrate) and ingress rules, all linked via symlinks to shared templates. A new encrypted secrets file (secrets.ejson) has been added, provisioning essential credentials for the staging instance, including database access, AWS keys, Sendgrid email services, GitHub OAuth, Avo admin license, and basic authentication for the UI.
config/deploy/staging · high confidence
Support for GitHub Actions as an OIDC trusted publisher
Users can now configure GitHub Actions workflows as trusted publishers for their gems. This change introduces a new model that validates repository, workflow, and environment details, and enables the system to verify OIDC tokens issued by GitHub Actions. It also adds support for verifying sigstore attestations generated by these workflows, ensuring that only authorized CI/CD pipelines can publish packages.
_app/models/oidc/trusted\publisher · high confidence
Security
New security incident notifications and standardized email templates
Users will now receive specific security notices regarding a legacy API key exposure incident ([GHSA redacted]), with separate emails for accounts where keys were already inactive versus those where active keys were revoked and require re-authentication. The email system has also been updated with a new standardized layout, including a reusable button component, dedicated templates for API key creation and revocation, and improved instructions for compromised accounts.
app/views/mailer · high confidence
Behavioural changes
API authorization now enforced via Pundit policies
API endpoints for RubyGems, ownership, and webhooks now require explicit authorization checks using Pundit policies. Access is determined by a combination of API key scopes (such as push\_rubygem, add\_owner, or access\_webhooks) and user-level permissions, with Multi-Factor Authentication (MFA) requirements enforced for sensitive actions like creating gems or modifying ownership. This change ensures that API requests are validated against specific scope permissions and user roles before execution.
app/policies/api · high confidence
API controllers refactored into a centralized base controller with new compact index and deprecation endpoints
The API controller structure has been reorganized to improve security, maintainability, and performance. A new \Api::BaseController\ centralizes common logic, including API key authentication, MFA verification, Pundit authorization, and session skipping, while removing the need for individual controller boilerplate. A new \Api::CompactIndexController\ implements the v2 compact index protocol, supporting range requests, ETags, and SHA-256 digests for efficient gem metadata retrieval. Additionally, an \Api::DeprecatedController\ now returns a 403 Forbidden status for legacy plugin versions, guiding users to update. These changes streamline API access control and enhance response caching and integrity verification for gem consumers.
app/controllers/api · high confidence
Add Pundit policies for OIDC trusted publishers
New authorization policies have been introduced for managing OIDC trusted publishers, restricting access based on user ownership and organizational roles. The \PendingTrustedPublisherPolicy\ allows users to view, create, and delete pending publisher records only for records they own. The \RubygemTrustedPublisherPolicy\ restricts viewing, creating, and deleting trusted publisher records for a specific Ruby gem to users who are owners of that gem and hold at least the admin role within the associated organization.
app/policies/oidc · high confidence
Admin actions migrated to a unified, audited base class
The admin panel's Avo actions now inherit from a new \ApplicationAction\ base class that enforces a mandatory audit comment (minimum 10 characters) and wraps every operation in an audited transaction, ensuring all administrative changes are logged. This refactor also standardizes error handling by reporting exceptions via \Rails.error\ and keeps the UI modal open on failure, while preserving the specific capabilities of each action such as user deletion, API key management, and gem yanking.
app/avo/actions · high confidence
Admin authorization now uses a custom Pundit client to scope policies
The admin interface now uses a dedicated \Admin::AuthorizationClient\ to handle authorization checks. This change ensures that Pundit policies for admin resources are automatically scoped under the \:admin\ namespace, keeping them separate from global policies and allowing for more granular access control within the admin area.
lib/admin · high confidence
Admin dashboard now displays key metrics and push activity charts
The admin dashboard has been updated to include a new layout with specific metric cards and a chart. Users can now see the total number of users, as well as counts for RubyGems and versions pushed, with the latter two supporting time-range filters (7 days, 30 days, 60 days, 365 days, Today, Month to date, Quarter to date, Year to date, and All). Additionally, a line chart visualizes the number of pushes by day over the last 30 days. These components are arranged in a grid and are visible only to users with the 'rubygems-org' team membership.
app/avo/cards, app/avo/dashboards · high confidence
Admin namespace protected by GitHub OAuth
The new admin dashboard area is now secured by requiring GitHub OAuth authentication. A base controller for the admin namespace has been introduced, which includes the GitHub OAuthable module to enforce this protection, and provides a logout action to end the admin session.
app/controllers/admin · high confidence
Admin panel resources migrated to Avo 3
The admin panel's resource definitions have been upgraded to Avo 3, introducing a new configuration structure and UI components. This change adds dedicated admin views for new capabilities such as organization management (including invites, memberships, and onboarding), API key administration (with rename and revocation actions), and OIDC-based trusted publishing (covering providers, roles, and pending publishers). It also enhances existing resources with new filters and actions, including user creation and deletion, gem name reservations, and attestation repair, while updating search and display logic across resources like users, gems, and versions.
app/avo/resources · high confidence
Agent skills directory restructured
The .claude/skills path is now a symbolic link pointing to ../.agents/skills, centralizing agent skill definitions in the .agents directory.
.claude · high confidence
Audit logging requires a mandatory comment for resource actions
A new concern, AvoAuditableResource, has been added to enforce audit logging for Avo resource actions. When creating, updating, or destroying records, users are now required to provide a comment of at least 10 characters explaining the action, which is then saved to the audit log. This ensures that all significant changes to resources are traceable with context.
app/avo/resources/concerns · high confidence
Authenticated users can now view MFA status and warnings in their profile
The introduction of the \User::WithPrivateFields\ module modifies the user profile payload to include private multi-factor authentication details. When a user retrieves their own profile, the response now contains an \mfa\ field reflecting their current MFA level and a \warning\ field that provides localized guidance if MFA is recommended but not yet enabled or is set to a weak level. This allows users to see their security posture directly in the API response without exposing these sensitive details in public profiles.
app/models/user · high confidence
Avo 3 field view components for array, nested, and JSON fields
The admin interface's Avo fields now use dedicated view components for rendering in index, show, and edit contexts. Array fields support adding and removing nested items with error display, nested fields render their sub-fields in tables or lists, and JSON fields display formatted output in index views. These changes update how these specific field types are presented in the admin panel.
app/components/avo/fields · high confidence
Avo JavaScript loaded via Importmap
The Avo administration interface now loads its custom JavaScript assets using the Importmap system. This change replaces the previous asset loading mechanism with a new partial that explicitly includes the 'avo.custom' script via importmap tags, ensuring consistent and modern module resolution for Avo's client-side functionality.
app/views/avo/partials · high confidence
Compact index v2 format with content-addressable checksums
The compact index has been upgraded to a v2 format that includes content-addressable checksums and Ruby ABI information for each gem version. This change introduces new data structures (GemVersionV2) and serialization logic to embed checksums and platform-specific details directly into the versions list, enabling more efficient and reliable gem resolution for users.
_lib/compact\index · high confidence
Database schema and seed data updated for Rails 8.1
The database schema has been regenerated to reflect the current state of the application, now targeting ActiveRecord version 8.1 (schema version 2026\_09\_04\_073906). This update includes new tables and columns such as \admin\_github\_users\ for storing admin GitHub user data, \api\_keys\ with polymorphic ownership and scope arrays, \attestations\ for gem attestation data, and \deletions\ to track yanked versions. The seed data has been updated to create initial organizations, memberships, users, and gems that exercise these new structures, including API keys and admin users.
db · high confidence
Downloads API endpoints return 410 Gone
The new \Api::V1::Versions::DownloadsController\ explicitly deprecates the \index\ and \search\ endpoints by returning a 410 Gone status with a plain-text message indicating they are no longer supported. This change removes access to version download statistics via the API, signaling that these features have been retired or moved.
app/controllers/api/v1/versions · high confidence
Enhanced security, logging, and request handling infrastructure
This change introduces several foundational improvements to the application's request processing and observability. Security is hardened by adding a dedicated markdown rendering module that sanitizes HTML output using a strict allowlist of tags and attributes, preventing potential XSS vulnerabilities in policy pages. Request handling now includes robust IP address resolution with Fastly edge verification via proxy tokens, enabling accurate geo-IP tracking only for verified traffic while correctly identifying bypassed requests. Observability is significantly improved with a new structured logging payload that captures detailed context including the acting user or API key owner, HTTP details, and edge bypass status, alongside a new user-agent parser that accurately identifies clients like Bundler, RubyGems, and OIDC actions for better telemetry.
lib/gemcutter · high confidence
Gems directory converted to a symlink
The server/gems directory is now a symbolic link pointing to the cache directory, replacing the previous unpacked structure. This change simplifies the file layout by removing the need to maintain a separate unpacked gems folder, as the gems are now accessed via the symlink.
server · high confidence
Homepage redesign with new search and support sections
The homepage has been completely redesigned to feature a prominent, large search box with autocomplete functionality, a display of the total download count, and a call-to-action to install RubyGems. Additionally, a new section highlights the platform's supporters and provides a direct link to donate via Ruby Central, replacing previous layout elements with a modern, responsive design using Tailwind CSS classes.
app/views/home · high confidence
Introduce Stimulus.js for interactive UI components
The application now uses Stimulus.js to manage client-side interactivity, replacing previous JavaScript implementations. This change introduces a suite of new controllers that enhance user experience: the autocomplete controller provides a responsive search-as-you-type experience with keyboard navigation; the password strength controller offers real-time visual feedback on password complexity; the onboarding name controller automatically generates URL-safe organization handles from display names; and the dump controller dynamically fetches and renders PostgreSQL database dump links from S3. Additional controllers handle specific UI behaviors such as avatar fallbacks, dialog management, dropdown toggles, and exclusive checkbox logic, creating a more consistent and maintainable frontend architecture.
app/javascript/controllers · high confidence
Introduce dedicated API key management and hardened authentication controllers
This change introduces a new ApiKeysController for managing user API keys (create, edit, update, destroy, and bulk reset) and a CompromisedPasswordsController to handle password reset flows flagged by HIBP checks. It also adds a new AvatarsController to proxy Gravatar images with caching, and a new OAuthController to handle GitHub OAuth for admin access. The ApplicationController is updated to include new security and caching helpers (like \deny\_shared\_cache\_when\_authenticated\ and \fastly\_expires\_in\), and several existing controllers (EmailConfirmations, MultifactorAuths, Passwords) are refactored to use stricter \params.expect\ and MFA verification flows.
app/controllers · high confidence
Introduce new ActionMailer-based email delivery and tracking
The application now uses a dedicated \ApplicationMailer\ base class that integrates SemanticLogger for delivery tracking and Roadie for automatic CSS inlining in HTML emails. All email notifications—including those for account changes, security events (MFA, API keys, password resets), gem operations (push, yank, ownership changes), organization invitations, and policy announcements—are now delivered via ActionMailer with ActiveJob backgrounding. This ensures emails are sent asynchronously and their delivery is logged as user events for monitoring.
app/mailers · high confidence
Introduces Pundit-based authorization for organizations, memberships, and gem ownerships
This change replaces previous access-control mechanisms with a new Pundit policy layer for the \app/policies\ directory. It introduces granular authorization for organization management (creating, updating, adding/removing gems, managing memberships, and reserving gem names) based on specific roles such as \:owner\, \:admin\, and \:maintainer\. It also standardizes ownership checks for RubyGems, ensuring that actions like adding, updating, or removing owners, as well as configuring trusted publishers, require appropriate ownership or organizational roles. This provides a consistent, role-based permission model for users interacting with organizations and gem ownerships.
app/policies · high confidence
Major API v1 controller refactoring and feature expansion
The API v1 controllers have been completely rewritten and expanded. New capabilities include an Activities API (latest and just\_updated endpoints), an Attestations endpoint for content-addressable gem support, a Deletions controller for yanking gems with Ruby ABI targeting, and a TimeframeVersions endpoint for querying versions by creation date. The Owners controller now supports role-based ownership management and lists gems by owner handle. The API Keys controller has been restructured to support scoped keys with MFA requirements and expiration dates. The Rubygems controller now accepts sigstore attestations during push and includes CORS support. Search functionality has been migrated to Elasticsearch with query sanitization and autocomplete. The Dependencies endpoint has been deprecated with a 404 response. Existing endpoints like Downloads, Profiles, and WebHooks have been refactored to use strong parameters, improved caching, and consistent JSON/YAML responses.
app/controllers/api/v1 · high confidence
Migrate JavaScript module loading to Importmap and restructure application entry points
The application now uses Importmap for JavaScript module resolution, replacing previous bundling or script-tag methods. The new \application.js\ entry point explicitly imports core libraries (Turbo, Rails UJS, LocalTime) and specific feature modules (OIDC API key form, pages, webauthn, github-buttons), while disabling Turbo's default drive behavior. Additionally, Avo admin customizations are now loaded via a dedicated \avo.custom.js\ file that registers the \stimulus-rails-nested-form\ controller, centralizing Stimulus controller registration.
app/javascript · high confidence
Migrate admin policies to the Admin:: namespace with Avo integration
All admin-facing Pundit policies have been moved into the Admin:: namespace (e.g., Admin::RubygemPolicy) and updated to inherit from a new Admin::ApplicationPolicy base class. This change introduces explicit Avo-specific permission methods (such as avo\_index?, avo\_show?, and act\_on?) to control access to the admin dashboard, and adds a has\_association helper to automatically define view permissions for related records. For users, this ensures that admin panel access is consistently enforced via the new policy structure, with scope resolution and association visibility properly scoped to rubygems\_org\_admins or specific user contexts.
app/policies/admin · high confidence
Migrate background jobs to ActiveJob with GoodJob adapter
The application has replaced the previous background job system with ActiveJob, using GoodJob as the adapter. This introduces a unified ApplicationJob base class with default retry policies and automatic discarding of deserialization errors. All existing background tasks—including gem indexing, Fastly log processing, CDN purging, webhook notifications, and user deletion—have been converted to ActiveJob jobs, allowing for better queue management, concurrency control, and observability via StatsD metrics.
app/jobs · high confidence
Migrate frontend scripts to vanilla JavaScript
The JavaScript codebase in app/javascript/src has been rewritten using vanilla JavaScript, removing the previous dependency on jQuery. This change includes new implementations for OIDC API key role forms (handling nested field addition/removal), MFA section toggling on the gems page, dynamic loading of transitive dependency lists, and WebAuthn credential registration and session handling. Users will experience the same functionality with a lighter, modern JavaScript stack that no longer relies on the jQuery library.
app/javascript/src · high confidence
Migrate to Tailwind CSS v4 configuration syntax
The application's Tailwind CSS setup has been updated to use the v4 configuration style. The main stylesheet now uses the new \@config\, \@import "tailwindcss"\, and \@plugin\ directives to load core styles and the forms, aspect-ratio, and typography plugins, replacing the previous compilation method.
app/assets/tailwind · high confidence
Multi-step UI for transferring RubyGems to an organization
The RubyGems transfer flow now uses a redesigned, multi-step interface that guides users through selecting the target organization, choosing which gems to transfer, and managing member permissions before finalizing. This update introduces a progress stepper, a summary view, and specific UI components for each step, including a 'Select all' checkbox for gems and a permission details accordion that explains the roles (Outside Contributor, Maintainer, Admin, Owner) available when inviting existing gem owners to the organization.
app/views/rubygems/transfer · high confidence
New admin access constraints for Rubygems.org
Added lib/constraints/admin.rb which defines access control logic for the admin interface. The file introduces a Matcher class that retrieves the admin user from the request header and validates their status, and a RubygemsOrgAdmin constraint that restricts access to users who are valid admins and specifically members of the 'rubygems-org' team. The file also enables frozen string literals for safety and performance.
lib/constraints · high confidence
New controller concerns for API keys, MFA, and auditing
This change introduces a suite of new controller concerns in the application to centralize and standardize key security and administrative behaviors. The \ApiKeyable\ concern provides utilities for generating and hashing unique RubyGems API keys. \ApplicationMultifactorMethods\ and \MfaExpiryMethods\ handle MFA redirection logic and session expiry management, ensuring users are guided to settings when MFA is required or expired. \RequireMfa\ and \SessionVerifiable\ enforce multi-factor authentication and session verification flows, including WebAuthn integration via \WebauthnVerifiable\. Additionally, \AvoAuditable\ and \MaintenanceTasksAuditable\ add audit logging capabilities to admin actions, while \JwtValidation\ and \LatestVersion\ handle JWT parsing and version lookups. These concerns replace scattered logic with reusable, testable components for authentication, authorization, and admin auditing.
app/controllers/concerns · high confidence
New dedicated admin login page with GitHub OAuth and dev mode support
Admin users now access the admin panel via a new, standalone login page at /avo/login.html.erb. This page provides a primary 'Log in with GitHub' button that initiates OAuth authentication (with Turbo disabled to ensure reliable session handling) and includes a fallback for development environments: when ENABLE\_DEVELOPMENT\_LOG\_IN is active, admins can directly log in as any existing GitHub admin user from a list, or create one by running db:seed. The page also links back to the main RubyGems.org site.
app/views/avo · high confidence
New global stylesheet with dialog and scrollbar utilities
A new global stylesheet (hammy.css) has been introduced to manage application-wide styles. This file defines specific styling for modal dialogs, including a semi-transparent backdrop that adapts to the system's dark mode preference, and provides utility classes to hide scrollbars across major browsers. It also includes a high-priority utility class to hide list items, ensuring it overrides conflicting Tailwind display utilities.
app/assets/stylesheets · high confidence
New maintenance page with status link and SVG asset
A new maintenance page has been added at public/maintenance/index.html, replacing previous inline or base64 assets with an external SVG image (gem\_wrench.svg) and a link to the real-time status page at status.rubygems.org. The page displays a simple 'Under maintenance' message and uses the site's static stylesheet.
public/maintenance · high confidence
New site layout system with breadcrumbs, session dialogs, and policy banners
The application introduces a new layout architecture in the views/layouts directory to support the redesigned user interface. This includes a new \_breadcrumbs.html.erb partial that renders a responsive, accessible breadcrumb trail for navigation context. A new \_session.html.erb partial replaces the previous header session controls, implementing a native HTML \<dialog\> component for the user profile menu and sign-in/sign-up actions. Additionally, a \_policies\_acknowledgement\_hammy.html.erb partial has been added to display a dismissible banner for new Terms of Service and Privacy Notice, allowing users to review and accept policies directly from the layout. These components are integrated into the main application.html.erb layout, which now serves as the base for specialized layouts like onboarding and subject (profile/organization) pages.
app/views/layouts · high confidence
Notifications for webhook deletion and automatic disabling
Users will now receive email notifications when a webhook is deleted or automatically disabled due to persistent failures. The new mailer views provide both HTML and text formats, detailing the specific webhook URL, the associated Ruby gem (if applicable), the reason for the action, and the number of failures that triggered the change.
_app/views/web\_hooks\mailer · high confidence
Production deployment configuration migrated to Kubernetes manifests and secrets
The production deployment configuration has been updated to use Kubernetes-native resources. Most deployment manifests (web, jobs, ingress, service, nginx config, etc.) are now implemented as symbolic links to shared templates, centralizing configuration management. Additionally, a new \secrets.ejson\ file has been added to store encrypted production secrets, including database URLs, AWS credentials, API keys for services like SendGrid and Fastly, and OAuth tokens, replacing previous secret management methods.
config/deploy/production · high confidence
Rails 7.2 configuration update and application booting improvements
The application's configuration initializers have been updated to align with Rails 7.2, including the adoption of the \:json\ cookie serializer and the \same\_site: :strict\ policy for session cookies. The boot process now enables the Zeitwerk autoloader, configures YJIT for performance, and registers custom ActiveModel types for Global ID and Duration. Additionally, the update introduces a cookie rotator to support graceful \secret\_key\_base\ rotation without forcing user logouts, and configures the application to use Semantic Logger for unified logging across components like Datadog, GoodJob, and Honeybadger.
config/initializers · high confidence
Rails 8.0 environment configuration overhaul
The application environment files (development, test, staging, production) have been updated to align with Rails 8.0 defaults and best practices. Key changes include replacing \config.eager\_load\ with \config.enable\_reloading\ for controlling code reloading, disabling \config.action\_dispatch.show\_exceptions\ in the test environment to prevent debug template rendering issues, and enforcing random test execution order via \config.active\_support.test\_order = :random\. The production and staging environments now explicitly configure Memcached with a 2MB value max size and JSON semantic logging, while the development environment supports a \PROFILE\ environment variable to switch to production-like settings for benchmarking.
config/environments · high confidence
Redesign of the gem dependencies page with reverse dependencies
The gem dependencies view has been completely redesigned to present dependencies in a structured table format, separating runtime and development scopes. The page now explicitly displays required version constraints for each dependency and includes a new section listing reverse dependencies (gems that depend on the current gem), showing their latest version, release date, and download counts. This replaces the previous list-based layout with a more detailed, tabular presentation that improves readability and provides deeper context about the gem's ecosystem.
app/views/dependencies · high confidence
Redesigned API key management with granular scopes and expiration
The API keys settings page has been redesigned to support more granular control and security. Users can now create and edit API keys with specific gem scopes, set expiration dates, and enable multi-factor authentication (MFA) on a per-key basis. The interface displays all gems if no specific gem scope is selected, and the key index view has been paginated for better usability. Additionally, the form has been converted to use Stimulus controllers for exclusive checkbox behavior, and the layout has been updated to use Tailwind CSS classes.
_app/views/api\keys · high confidence
Redesigned MFA verification and recovery code pages
The multifactor authentication verification and recovery code views have been redesigned with a modern UI, featuring a centered card layout, dark mode support, and updated styling. The MFA prompt page now consolidates WebAuthn and TOTP/recovery code entry into a single flow, while the recovery code page introduces a clickable copy-to-clipboard feature for the generated codes and requires explicit user acknowledgment before continuing.
_app/views/multifactor\auths · high confidence
Redesigned OIDC API key roles and trusted publisher management interfaces
The OIDC settings pages have been redesigned to use Phlex view components, providing a modernized interface for managing API key roles, access policies, and trusted publishers. Users can now create and edit API key roles with granular access policies (defining effects, principals, and conditions), view detailed permission scopes, and manage GitHub Actions workflow integrations. The redesign also introduces dedicated pages for listing and configuring trusted publishers (including GitHub Actions) for both global and per-gem contexts, with improved navigation, consistent styling, and clearer presentation of configuration details.
app/views/oidc · high confidence
Redesigned TOTP setup interface with modern styling
The TOTP setup view has been redesigned to provide a cleaner, more modern user experience. The new interface features a centered card layout with improved typography and spacing, displaying the QR code, account details, and secret key more clearly. The input field for the OTP code now includes better visual feedback with focus states and uses a primary color button for submission, enhancing usability and accessibility.
app/views/totps · high confidence
Redesigned UI components using Phlex
The application's view layer has been migrated to Phlex, introducing a suite of new Ruby-based UI components (Alert, Button, Card, Tooltip, etc.) that replace the previous view templates. This change brings a consistent, modern design system with updated styling, dark mode support, and improved accessibility across the interface, including redesigned navigation, event tables, and OIDC/trusted publisher forms.
app/views/components · high confidence
Redesigned WebAuthn verification flow with dedicated status pages
The WebAuthn verification interface has been redesigned to provide clearer feedback during the authentication process. Users now encounter a dedicated prompt page that displays their name and initiates the WebAuthn session, replacing the previous generic view. Upon completion, the system redirects to distinct success or failure pages: the success page confirms the verification with a checkmark, while the failure page displays an error icon and any specific error message returned by the backend, helping users understand why the attempt did not succeed.
_app/views/webauthn\verifications · high confidence
Redesigned email confirmation request page
The email confirmation request interface has been updated with a modern, responsive design. Users now see a centered card layout with clear typography and form styling, including a dedicated email input field and a primary submit button, improving the visual consistency and usability of the email confirmation flow.
_app/views/email\confirmations · high confidence
Redesigned gem show and index pages with new layout and components
The gem show and index pages have been completely redesigned with a new layout structure. The main show page now uses a two-column layout with a new aside sidebar displaying version info, download counts, MFA status, and GitHub stars, alongside a secondary sidebar for links, licenses, and owners. The index page now uses a card-based layout with alphabet directory navigation. New components include tabbed navigation for gem info and dependencies, version navigation links, and dedicated views for yanked gems with unsubscribe options. The redesign also adds security event logging views, reserved namespace pages, and improved owner management displays with MFA warnings.
app/views/rubygems · high confidence
Redesigned organization membership management interface
The organization membership views have been completely redesigned with a new layout and styling. The members index page now displays a list of members with their roles (or 'pending' status for unconfirmed invitations) and provides an invite button for authorized users. A new edit page allows administrators to change a member's role and includes a 'Joined' date for confirmed members, as well as a button to resend invitations to pending members. The new invitation page enables admins to invite new members by entering a user handle and selecting a role. All views use a consistent card-based layout with breadcrumb navigation.
app/views/organizations/members · high confidence
Redesigned organization onboarding flow with step-by-step wizard
The organization creation process has been restructured into a multi-step wizard to guide users through setup more clearly. The new flow includes distinct stages for naming the organization (including the permanent handle), selecting associated gems, and managing member invitations, all tracked by a visual progress indicator. A summary view is now available at each step to review selections, and the final confirmation screen explicitly warns that the organization handle is permanent and cannot be changed without support assistance.
app/views/organizations/onboarding · high confidence
Redesigned owners management interface with role-based access and self-removal confirmation
The owners index and edit pages have been redesigned to use a new layout, featuring a responsive table that displays owner name, confirmation status, MFA status, authorizer, role, and confirmation date. Users can now add new owners by specifying a handle and selecting a role, and existing owners can have their roles updated via the edit page. A key behavioral change is the requirement for username confirmation when a user attempts to remove themselves as an owner, adding a safety step to prevent accidental loss of access.
app/views/owners · high confidence
Redesigned password reset and edit forms with API key reset options
The password reset workflow now uses custom, redesigned views for requesting a reset link (new), entering a new password (edit), and confirming success (create). The edit form includes a password strength meter, displays alerts if the password was found in a breach (HIBP), and allows users to optionally reset their API keys or all scoped API keys during the password change. The forms use modern styling with dark mode support and Turbo-disabled submission for the edit action.
app/views/passwords · high confidence
Redesigned reverse dependencies page with new search and table layout
The reverse dependencies view has been completely rewritten to feature a modern, responsive design. Users now see a dedicated search form at the top of the page to filter reverse dependencies by query. The list of dependencies is displayed in a clean table format showing the gem name, version, date, and download counts, with mobile-friendly adjustments that hide less critical columns on smaller screens. Pagination has been simplified to use a 'plain paginate' helper, removing the explicit page number links in favor of a more streamlined navigation experience.
_app/views/reverse\dependencies · high confidence
Redesigned search interface with advanced filtering and aggregation stats
The search experience has been redesigned to include a dedicated Advanced Search page and enhanced result displays. Users can now access advanced filtering options via a new form that allows searching by name, summary, description, downloads, and update date, powered by a Stimulus.js controller for interactive input handling. Search results pages now feature a new aggregation bar that displays match counts for different fields, date range filters, and yanked gem status, alongside improved pagination and search suggestion prompts. The layout utilizes new UI components like CardComponent and RubygemComponent for a consistent visual style.
app/views/searches · high confidence
Redesigned settings page with WebAuthn support and new account navigation
The settings edit page has been redesigned to include a dedicated section for managing WebAuthn credentials, displaying a status badge and allowing users to add new keys. The Multi-Factor Authentication (MFA) section now explicitly shows the MFA level for enabled accounts and provides controls for TOTP. Additionally, the Account section has been updated to include direct links to API keys, OIDC pending trusted publishers, and OIDC API key roles, improving visibility for these features.
app/views/settings · high confidence
Redesigned sign-in and verification pages with modern styling
The sign-in and password verification pages have been updated with a new visual design, featuring a centered card layout, improved spacing, and support for dark mode. The login form now accepts either an email address or a handle in the 'who' field, and the password input includes the 'current-password' autocomplete attribute to assist password managers. Additionally, the verification page now conditionally displays a WebAuthn prompt if the user has multi-factor authentication enabled.
app/views/sessions · high confidence
Redesigned static pages with new content and components
The static pages in the application have been completely redesigned and updated. The About page now features a structured layout with purpose statements, founding history, and sponsor acknowledgments, including a direct link to download logos. The Download page has been updated to display the latest RubyGems version dynamically, providing clear manual and automatic upgrade instructions alongside buttons for various distribution formats (tgz, zip, gem, git). A new Data page offers access to sanitized weekly PostgreSQL data dumps, utilizing a Stimulus.js controller for dynamic list rendering. The Security page has been restructured to clarify reporting procedures for RubyGems client issues versus gem vulnerabilities, explicitly stating that monetary bug bounties are no longer offered, and includes a direct link to the new Security Engineers in Residence FAQ. This FAQ page details the new program funded by Alpha-Omega and run by Ruby Central, explaining the team's process for scanning, verifying, and disclosing vulnerabilities in the Ruby ecosystem. The Supporters page now highlights the RubyGems Supporter Program, listing open-source sponsors and infrastructure donors. Additionally, a new index page provides a central list of all available static pages.
app/views/pages · high confidence
Redesigned stats page with modern UI and pagination
The stats page has been completely redesigned with a modern, responsive layout using Tailwind CSS classes for cards, grids, and typography. Key changes include the addition of pagination for the 'most downloaded gems' list (using the Kaminari gem), improved number formatting with delimiters, and the integration of a Stimulus.js controller for animated download meters. The page now features a cleaner visual hierarchy with icon-tagged labels, a prominent 'Click Gems' call-to-action button, and dark mode support.
app/views/stats · high confidence
Redesigned user dashboard with sidebar navigation and organization promotion
The dashboard view has been completely redesigned to feature a new layout with a sidebar navigation component (\\_subject.html.erb\) that includes links to the dashboard, subscriptions, settings, and organizations (for members). The main content area now displays a promotional banner for the new Organizations feature (visible only to users with the feature flag enabled and no existing memberships), followed by cards showing the user's latest gem updates, owned gems, and subscribed gems. This change introduces a modern UI structure with Tailwind CSS styling and integrates the new Organizations capability directly into the user's primary landing page.
app/views/dashboards · high confidence
Redesigned user profile pages with modern UI and new security features
The user profile experience has been completely overhauled with a new visual design, introducing dedicated pages for viewing profile details, editing settings, and deleting accounts. The public profile now displays the user's handle, full name, email (if public), and X/Twitter username, alongside a list of their published gems with version and download counts. Users can now edit their profile to update their handle, Twitter username, email, and full name, with validation requiring a password for changes. A new 'Delete Profile' page allows users to permanently remove their account, listing any gems they solely own that would be affected. Additionally, a new Security Events view has been added, allowing users to review their account's security activity via a dedicated Phlex-based component.
app/views/profiles · high confidence
Redesigned user sign-up form with handle and public email options
The user sign-up experience has been redesigned with a new form layout that now requires users to set a handle in addition to their email and password. The form includes a new optional full name field and a checkbox to allow users to make their email public. The password field has been updated to include the autocomplete attribute set to 'new-password' for better security and browser compatibility. The sign-up page also displays a link to the terms of service and respects the signup\_enabled? configuration to allow or disable new registrations.
app/views/users · high confidence
Redesigned versions list and added Atom feeds
The versions index page has been redesigned with a modern layout, displaying version numbers, dates, platforms, Ruby ABI, and file sizes in a paginated list. A new partial renders individual version items with styling for yanked gems. Additionally, Atom feeds have been added for both the global latest gems and per-gem version histories, allowing users to subscribe to version updates.
app/views/versions · high confidence
Refactored admin authentication and added new middleware for hosting and redirects
Admin authentication logic has been extracted into a dedicated \AdminAuth\ middleware, which now handles GitHub OAuth for the \/admin\ namespace and ensures session cookies are set on the login page, while explicitly allowing unauthenticated access to \/oauth\ paths. A new \Hostess\ middleware manages static file serving for gem specs and indexes, including tracking downloads for \.gem\ files. Additionally, a \Redirector\ middleware enforces canonical hostnames by redirecting requests from non-allowed hosts to the primary site, excluding API and internal paths.
lib/gemcutter/middleware · high confidence
Restrict RubyGem event management to owners
A new policy for RubyGem events has been introduced that restricts all write operations (create, update, and destroy) to return false, effectively disabling these actions for all users. The only permitted action is viewing events (show), which is now gated by an ownership check, allowing access only if the current user owns the associated RubyGem.
app/policies/events · high confidence
SQS worker now enqueues Fastly log processing jobs via Active Job
The SQS worker has been updated to process incoming S3 log records by creating LogTicket records and enqueuing FastlyLogProcessorJob instances using Active Job, replacing the previous direct processing logic. This change introduces StatsD instrumentation to track metrics for fetched entries, enqueued jobs, and duplicate record attempts, and ensures the worker class is properly loaded by adding the lib folder to eager\_load\_paths.
lib/shoryuken · high confidence
Standardize styling for static pages and admin login
A new static stylesheet (static.css) has been introduced to centralize visual presentation for error pages and the admin login interface. This change removes previously inline styles from error pages, ensuring consistent typography, layout, and spacing across these views. It also defines specific styles for the admin login button and error illustrations, including a bounce animation for the error page graphic, replacing the previous ad-hoc styling approach.
public/stylesheets · high confidence
Standardized error pages and search configuration
The site now serves consistent, branded HTML error pages for client and server errors (400, 403, 404, 406, 422, 500, 502, 503) using a unified layout and SVG illustrations. Search engine indexing is controlled via a new robots.txt file that disallows /search, /downloads, /gems?letter=\*, /names, and /news. Additionally, an OpenSearch description file has been added to enable native browser search integration for RubyGems.org.
public · high confidence
Upgrade to Rails 8.1 defaults and modernize application configuration
The application configuration has been updated to load Rails 8.1 framework defaults, bringing new baseline behaviors and security settings. This change includes migrating the background job adapter to Good Job, enabling the bootsnap caching library for faster boot times, and configuring the middleware stack with Rack::Sanitizer, Rack::Attack, and Rack::Deflater. Additionally, the application now uses Flipper for feature flagging, sets the Cross-Origin-Opener-Policy to same-origin for improved security, and configures specific autoload paths for views and components.
config · high confidence
Test coverage
Added Fastly sample log fixture for testing; Added admin policy tests for Avo dashboard resources; Added component tests and Lookbook previews; Added factory for MaintenanceTasks::Run; Added functional tests for API v1 controllers; Added functional tests for API v2 contents and versions endpoints; Added functional tests for OIDC API key roles controller; Added functional tests for core controllers; Added functional tests for organization features; Added functional tests for organization onboarding controllers; Added functional tests for the RubyGems transfer workflow; Added integration test for GoodJob admin dashboard access; Added integration tests for API v1 endpoints; Added integration tests for API, security, and organizational features; Added integration tests for Avo admin dashboard resources; Added integration tests for OIDC profile pages; Added integration tests for the API v2 version information endpoint; Added mailer previews and automated tests for email notifications; Added model tests for API keys, attestations, and gem management; Added model tests for Admin::GitHubUser; Added model tests for MFA, search, and compact index concerns; Added policy tests for API authorization; Added policy tests for organization, membership, and gem ownership authorization; Added system tests for new and redesigned UI features; Added test coverage for OIDC model validations and relationships; Added test coverage for background job suite; Added test coverage for mailer templates and delivery behavior; Added test factories for OIDC integration testing; Added test factories for core domain models; Added test factories for security event logging; Added test fixture for sigstore attestation verification; Added tests for API deprecation routing; Added tests for Gemcutter configuration loading; Added tests for MFA warning logic in user JSON serialization; Added tests for OIDC Trusted Publisher GitHub Action model; Added tests for OIDC trusted publisher policies; Added tests for RSTUF job lifecycle; Added tests for Rubygem event policy; Added tests for access control, compact index, markdown rendering, password breach checking, and search query sanitization; Added tests for compact index dependency and version handling; Added tests for internal ping and revision endpoints; Added tests for maintenance tasks; Added tests for the audit attestation subject digest rake task; Added tests for the versions downloads controller; Added tests for user, rubygem, and user agent event models; Added unit tests for Avo admin actions and filters; Added unit tests for Duration and JsonDeserializable types; Added unit tests for Hostess and Redirector middleware; Added unit tests for certificate chain serialization, ERB safety, and infrastructure components; Added unit tests for helper methods; Added unit tests for request IP address handling and user agent parsing; Added unit tests for the RSTUF API client; Integration tests for OIDC API endpoints; Integration tests for the Compact Index API; Migrate system tests to Playwright and establish new test infrastructure; New test helpers for admin, API policies, Avo, compact index, Datadog, email, search, feature flags, gems, OAuth, passwords, policies, rake, rate limits, and WebAuthn; System tests for Avo admin actions.
Dependencies
Upgrade Ruby to 3.4.3 and RubyGems to 3.6.8
The application runtime has been upgraded to Ruby 3.4.3, with RubyGems updated to version 3.6.8. This ensures the application runs on the latest stable Ruby release, providing performance improvements and security patches.
(dependencies) · high confidence
Upgrades Stimulus to v3.2.2 and adds @rails/ujs v7.1.3-4
The vendor JavaScript bundle now includes @hotwired/stimulus version 3.2.2 and @rails/ujs version 7.1.3-4. This update brings the latest Stimulus features and bug fixes to the application's controller system, while the inclusion of @rails/ujs provides legacy unobtrusive JavaScript helpers (such as remote form handling and CSRF protection) that may be required by existing views or gems like Avo.
vendor/javascript · high confidence
Housekeeping
Added empty reports directory placeholder; Placeholder for asset builds directory.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 49.
Lenses
- Code Health 70
- Architecture 88
- Maturity 56
- Readiness 80
- Security 50
- Domain Modelling 41
- Accessibility 56
Changes since last survey
- 300 commits — 275 feature/other, 25 fixes
By area
- (root) — 69 commits
- (repo) — 55 commits
- .github/workflows — 21 commits
- app/models — 21 commits
- app/views — 15 commits
- config/locales — 13 commits
- db/migrate — 13 commits
- app/controllers — 12 commits
- config/initializers — 12 commits
- app/avo — 10 commits
- config/deploy — 7 commits
- test/functional — 7 commits
- test/models — 6 commits
- app/tasks — 4 commits
- .devcontainer/devcontainer-lock.json — 3 commits
- .github/actions — 3 commits
- .github/dependabot.yml — 3 commits
- lib/gemcutter — 3 commits
- test/integration — 3 commits
- .agents/skills — 2 commits
Notable commits
- fix: Fix Avo unblock user action (#6774)
- fix: Fix Deprecation: Use skip instead of add_filter for simplecov (#6732)
- fix: Fix GoodJob StatsD result counter (#6767)
- fix: Fix RuboCop refute assertions
- fix: Fix business logic events signup tracking (#6612)
- fix: Fix flaky Rails test failure in API v1 downloads yanked-gem case (#6809)
- fix: Fix gem transfer when co-owners are already organization members
- fix: Fix password reset links with strict SameSite cookies (#6794)
- fix: Fix password reset token migration (#6770)
- fix: Fix reusable workflow attestation verification (#6811)
- fix: Fix simple_markup for RDoc 8
- fix: Fix some more RuboCop refute assertions
- fix: Isolate the names cache to fix a flaky compact index test
- fix: Merge pull request #6728 from mvanhorn/fix/6695-owner-profile-latest-version
- fix: Merge pull request #6768 from rubygems/ab/fix-gem-transfer-existing-org-members
- fix: Merge pull request #6783 from rubygems/revert-abi
- fix: Merge pull request #6857 from rubygems/copilot/fix-rubocop-failure-again
- fix: Revert "Make version index cleanup idempotent (#6782)"
- fix: Revert "Merge pull request #6674 from Shopify/ho/feature-branch-ca-server-changes"
- fix: fix: read the admin header by name in the logger; lib/github_oauthable.rb loads before SimpleCov starts, so any line added there is uncovered (this is how it was before)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
rubygems/rubygems.org was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ad83daf211de083abcdaa61c7ae5cfb5d495fb01 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.